AppGallery Connect, mapped for the terminal

Move every release through one red line.

A Go command center for discovering, dry-running, and invoking AppGallery Connect APIs—with stable JSON for people, CI, and coding agents.

13 API families156 registered interfaces3 output formats
agc / productionreference mode
agcTerminalJSONAgentScript
One command surface. Your workflow.
AUTHPS256 / OAuth
PROFILEproject-bound
PACKAGEupload + status
RELEASEinvoke by choice

$ agc auth check --pretty

{
  "data": {
    "name": "production",
    "mode": "service-account",
    "active": true
  },
  "affordances": {
    "next": "agc publishing endpoints"
  }
}

project profile resolved · dry-run on

Dry-run firstNothing is sent until you opt in.
Agent-readableJSON envelopes include next actions.
One surfaceCLI, local REST, and web share a registry.

Install agc CLI

Use the package manager for your system.

macOS installs through the Createitv Homebrew tap with brew tap createitv/tap && brew install agc-cli. Windows installs through Scoop from the Createitv bucket.

macOS Homebrew command
$ brew tap createitv/tap && brew install agc-cli && agc version
Windows Scoop command
PS> if (!(Get-Command scoop -ErrorAction SilentlyContinue)) { Set-ExecutionPolicy RemoteSigned -Scope CurrentUser -Force; irm get.scoop.sh | iex }; scoop bucket add createitv https://github.com/Createitv/scoop-bucket; scoop install agc-cli; agc version
Homebrew formula: agc-cli Versioned GitHub Release binary Winget PR submitted for Microsoft review

The release rail

Context flows forward. Secrets do not.

Each stage owns one job. Credentials remain local, project context remains portable, and destructive API calls require an explicit switch.

01

AUTH

PS256 / OAuth

02

PROFILE

project-bound

03

PACKAGE

upload + status

04

RELEASE

invoke by choice

Automatic profile binding

Choose once per project. Override only when you mean it.

Bind production in .agc/project.json. Commands resolve the profile in a predictable order, while --profile staging remains available for one-off work.

  1. 1CLI override--profile staging
  2. 2Project default.agc/project.json
  3. 3Active account~/.agc/credentials.json
.agc/project.json project safe
{
  "appId": "123456789",
  "projectId": "987654321",
  "packageName": "com.example.app",
  "profile": "production"
}
No client keys or private keys are stored here.

Interface registry

Discover the API before writing the request.

Every entry carries its method, path, parameter locations, CLI command, REST route, and dry-run path.

Selected family / provisioning

Provisioning

registered

Certificates, profiles, ACLs, devices, and fingerprints for release workflows.

DISCOVERagc provisioning endpoints --output table
STATUSagc provisioning status --pretty
LOCAL REST/api/v1/provisioning
17 typed interface entries

All endpoints 17

Expand an endpoint for registered parameters and commands. Consult its reference for full schemas, responses, and permissions.

POST批量添加设备provision-api-add-device/api/publish/v2/device

此接口用于批量添加调试/测试设备。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-add-device --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-add-device

Dry run (supply required parameters first)

agc provisioning provision-api-add-device --invoke --dry-run=true --body body.json
Read endpoint reference ↗
POST新增证书指纹provision-api-add-fingerprints/api/provision/v1/fingerprints

此接口用于新增证书指纹。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-add-fingerprints --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-add-fingerprints

Dry run (supply required parameters first)

agc provisioning provision-api-add-fingerprints --invoke --dry-run=true --body body.json
Read endpoint reference ↗
POST申请证书provision-api-apply-cent/api/publish/v3/cert

此接口用于申请二进制证书、In-house发布证书、调试证书或发布证书。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-apply-cent --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-apply-cent

Dry run (supply required parameters first)

agc provisioning provision-api-apply-cent --invoke --dry-run=true --body body.json
Read endpoint reference ↗
POST申请Profileprovision-api-apply-provision/api/publish/v3/provision

此接口用于申请指定设备发布Profile、In-house发布Profile、调试Profile或发布Profile。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-apply-provision --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-apply-provision

Dry run (supply required parameters first)

agc provisioning provision-api-apply-provision --invoke --dry-run=true --body body.json
Read endpoint reference ↗
POST申请受限ACL权限provision-api-applyacl/api/provision/v1/user/permission/apply

此接口用于申请受限ACL权限。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-applyacl --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-applyacl

Dry run (supply required parameters first)

agc provisioning provision-api-applyacl --invoke --dry-run=true --body body.json
Read endpoint reference ↗
POST删除证书provision-api-delete-cent/api/publish/v2/cert/delete

此接口用于删除创建的证书。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-delete-cent --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-delete-cent

Dry run (supply required parameters first)

agc provisioning provision-api-delete-cent --invoke --dry-run=true --body body.json
Read endpoint reference ↗
POST删除设备provision-api-delete-device/api/publish/v2/device/delete

此接口用于删除已添加的设备。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-delete-device --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-delete-device

Dry run (supply required parameters first)

agc provisioning provision-api-delete-device --invoke --dry-run=true --body body.json
Read endpoint reference ↗
DELETE删除证书指纹provision-api-delete-fingerprints/api/provision/v1/fingerprints

此接口用于删除证书指纹。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Inspect definition

agc provisioning provision-api-delete-fingerprints --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-delete-fingerprints

Dry run (supply required parameters first)

agc provisioning provision-api-delete-fingerprints --invoke --dry-run=true
Read endpoint reference ↗
DELETE删除Profileprovision-api-delete-provision/api/publish/v2/provision

此接口用于删除申请的Profile。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Inspect definition

agc provisioning provision-api-delete-provision --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-delete-provision

Dry run (supply required parameters first)

agc provisioning provision-api-delete-provision --invoke --dry-run=true
Read endpoint reference ↗
POST查询可申请的ACL权限列表provision-api-eligible-acl/api/provision/v1/user/permission/apply/list

此接口用于查询指定APP ID下所有可申请的ACL权限列表。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-eligible-acl --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-eligible-acl

Dry run (supply required parameters first)

agc provisioning provision-api-eligible-acl --invoke --dry-run=true --body body.json
Read endpoint reference ↗
GET查询证书指纹provision-api-get-fingerprints/api/provision/v1/fingerprints

此接口用于查询已创建的证书指纹。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription
appIdheaderYes—Huawei application ID

Inspect definition

agc provisioning provision-api-get-fingerprints --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-get-fingerprints

Dry run (supply required parameters first)

agc provisioning provision-api-get-fingerprints --invoke --dry-run=true
Read endpoint reference ↗
GET查询已申请的受限ACL权限provision-api-getacl/api/provision/v1/user/permission

此接口用于查询申请的受限ACL权限信息。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription
appIdheaderYes—Huawei application ID

Inspect definition

agc provisioning provision-api-getacl --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-getacl

Dry run (supply required parameters first)

agc provisioning provision-api-getacl --invoke --dry-run=true
Read endpoint reference ↗
GET查询受限ACL权限的申请状态provision-api-getaclapplystatus/api/provision/v1/user/permission/apply/status

此接口用于查询受限ACL权限的申请状态,包含“申请中”和“审核通过”。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Inspect definition

agc provisioning provision-api-getaclapplystatus --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-getaclapplystatus

Dry run (supply required parameters first)

agc provisioning provision-api-getaclapplystatus --invoke --dry-run=true
Read endpoint reference ↗
POST查询证书provision-api-query-cent/api/publish/v3/cert/list

此接口用于查询创建的证书。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-query-cent --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-query-cent

Dry run (supply required parameters first)

agc provisioning provision-api-query-cent --invoke --dry-run=true --body body.json
Read endpoint reference ↗
GET查询设备列表provision-api-query-device/api/publish/v2/device/list

此接口用于查询当前设备的信息。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Inspect definition

agc provisioning provision-api-query-device --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-query-device

Dry run (supply required parameters first)

agc provisioning provision-api-query-device --invoke --dry-run=true
Read endpoint reference ↗
GET查询Profile列表provision-api-query-provision/api/publish/v3/provision/list

此接口用于查询申请的Profile。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Inspect definition

agc provisioning provision-api-query-provision --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-query-provision

Dry run (supply required parameters first)

agc provisioning provision-api-query-provision --invoke --dry-run=true
Read endpoint reference ↗
PUT修改Profile绑定的设备provision-api-update-provision/api/publish/v3/provision

此接口用于修改调试Profile绑定的调试设备,或者修改指定设备发布Profile绑定的测试设备。

Developer-to-Huawei API

Registered parameters
ParameterLocationRequiredTypeDescription

Parameters are not listed in the registry. See the reference.

Request body: json

Inspect definition

agc provisioning provision-api-update-provision --pretty

Local REST definition

/api/v1/provisioning/endpoints/provision-api-update-provision

Dry run (supply required parameters first)

agc provisioning provision-api-update-provision --invoke --dry-run=true --body body.json
Read endpoint reference ↗

What is agc-cli, and who is it for?

agc-cli is an open-source Go command-line tool for Huawei AppGallery Connect, maintained by Createitv. Its installed command is agc. It organizes API discovery, credential profiles, request previews, and API invocation into reusable commands for HarmonyOS and Huawei app developers who manage app metadata, testers, products, and reports.

Project and guides: GitHub · Usage guide · Issues

Frequently asked questions

Is agc-cli an official Huawei tool?

No. agc-cli is an independent open-source project maintained by Createitv under the MIT license. It organizes endpoints using Huawei AppGallery Connect API references and is not an official Huawei product or support service.

How do I install agc-cli on macOS, Windows, or Linux?

On macOS, run brew tap createitv/tap, then brew install agc-cli. On Windows, run scoop bucket add createitv https://github.com/Createitv/scoop-bucket, then scoop install agc-cli. On Linux, download a binary for your architecture from GitHub Releases. Run agc version to verify installation.

Is agc-cli free, and do I need an account?

agc-cli is free to use and modify under the MIT license. Calling Huawei APIs requires your own AppGallery Connect account, credentials, and permissions. Huawei service pricing and limits remain subject to Huawei terms. Browsing the endpoint reference or inspecting CLI definitions does not require login.

How do I query app information for the first time?

Save credentials with agc auth login --service-account-file ~/.agc/service-account.json --name production, then bind the project with agc init --app-id YOUR_APP_ID --default-profile production. Preview with agc publishing app-info-query --invoke --query appId=YOUR_APP_ID --query lang=en-US. Add --dry-run=false after checking the request. Supply a client_id header explicitly when required.

Are all 156 endpoints production-verified?

No. The registry contains 156 entries across 13 API families; this is registry coverage, not production verification of every endpoint. Registered parameters and command surfaces are shown here. Consult each endpoint reference for full request and response schemas, permissions, and business prerequisites.

Does the default dry run change my app?

No. Endpoint commands with --invoke preview the request without sending it by default. Real invocation requires --dry-run=false. Check the target app, credential profile, and parameters before executing.

Can I use agc-cli with scripts or AI agents?

Yes. JSON output supports script processing. agc capabilities and agc endpoints expose discovery; agc web-server provides local REST routes, and agc openapi exports the contract. Command templates support navigation but do not replace business-state checks or review decisions.

Does a project profile fill all endpoint parameters automatically?

A project configuration can select its default credential profile, with --profile for explicit overrides. App IDs, languages, headers, and request bodies still need to be supplied according to each endpoint. Keep Service Account private keys and credential files out of Git.

Browse the complete API reference by family

Content updated:

Quick start

Three commands to a bound, inspectable workspace.

Use placeholders for your AppGallery Connect values. The second command is what makes the profile automatic for this project.

01

Save a credential profile

Service Account is the preferred route. Secrets stay in ~/.agc/credentials.json with restricted permissions.

$ agc auth login --service-account-file ~/.agc/service-account.json --name production
02

Bind it to the project

Save project metadata and choose a default credential profile. Supply endpoint parameters explicitly when invoking APIs.

$ agc init --app-id <app-id> --project-id <project-id> --package-name com.example.app --default-profile production
03

Inspect before invoking

Endpoint commands are dry-run first. Review the exact method and URL, then opt into the real request.

$ agc publishing app-info-query --invoke --query appId=<app-id> --dry-run=false

Local command center

The browser is a window into the same registry.

Start the local REST server when you want live capability data. Without it, this site stays useful as a complete reference surface.

agc web-server --addr :8421
GET/api/v1/capabilitiesfamilies + affordances
GET/api/v1/endpointsall interface entries
GET/api/v1/openapi.jsonmachine-readable contract
POST/api/v1/:family/endpoints/:id/invokedry-run by default